Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-43441

Опубликовано: 16 мар. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

5.1.5+ds1-1
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

5.1.5+ds1-1
esm-apps/xenial

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

kinetic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 91%
0.06448
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
почти 3 года назад

A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 8.1
debian
почти 3 года назад

A code execution vulnerability exists in the Statement Bindings functi ...

CVSS3: 8.1
github
почти 3 года назад

sqlite vulnerable to code execution due to Object coercion

EPSS

Процентиль: 91%
0.06448
Низкий

8.1 High

CVSS3

Уязвимость CVE-2022-43441